{"id":"CVE-2023-48299","aliases":["GHSA-m2mj-pr4f-h9jp","PYSEC-2026-1972"],"url":"https://o3.security/vulnerability/CVE-2023-48299","summary":"TorchServe ZipSlip","details":"### Impact\nUsing the model/workflow management API, there is a chance of uploading potentially harmful archives that contain files that are extracted to any location on the filesystem that is within the process permissions. Leveraging this issue could aid third-party actors in hiding harmful code in open-source/public models, which can be downloaded from the internet, and take advantage of machines running Torchserve.\n\n### Patches\nThe ZipSlip issue in TorchServe has been fixed by validating the paths of files contained within a zip archive before extracting them: https://github.com/pytorch/serve/pull/2634\n\nTorchServe release 0.9.0 includes fixes to address the ZipSlip vulnerability:\nhttps://github.com/pytorch/serve/releases/tag/v0.9.0\n\n### References\nhttps://github.com/pytorch/serve/pull/2634\nhttps://github.com/pytorch/serve/releases/tag/v0.9.0\n\n### Credit\nWe would like to thank Oligo Security for responsibly disclosing this issue.\n\nIf you have any questions or comments about this advisory, we ask that you contact AWS Security via our [vulnerability reporting page](https://aws.amazon.com/security/vulnerability-reporting) or directly via email to [aws-security@amazon.com](mailto:aws-security@amazon.com). Please do not create a public GitHub issue.","published":"2023-11-21T20:55:59.504Z","modified":"2026-08-12T14:51:36.484883Z","cvss":{"score":5.3,"severity":"MEDIUM","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N"},"epss":{"score":0.00673,"percentile":0.49441,"asOf":"2026-08-21"},"cisaKev":null,"exploitsKnown":0,"affectedPackages":[{"ecosystem":"PyPI","name":"torchserve","fixedVersion":"0.9.0"}],"fix":{"url":"https://github.com/pytorch/serve/commit/bfb3d42396727614aef625143b4381e64142f9bb","label":"pytorch/serve@bfb3d42"},"references":[{"type":"WEB","url":"https://github.com/pytorch/serve/releases/tag/v0.9.0"},{"type":"ADVISORY","url":"https://github.com/CVEProject/cvelistV5/tree/main/cves/2023/48xxx/CVE-2023-48299.json"},{"type":"ADVISORY","url":"https://github.com/pytorch/serve/security/advisories/GHSA-m2mj-pr4f-h9jp"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2023-48299"},{"type":"FIX","url":"https://github.com/pytorch/serve/commit/bfb3d42396727614aef625143b4381e64142f9bb"},{"type":"FIX","url":"https://github.com/pytorch/serve/pull/2634"},{"type":"PACKAGE","url":"https://github.com/pytorch/serve"}],"provenance":{"sources":["OSV.dev","FIRST.org (EPSS)"],"lastVerified":"2026-08-12T14:51:36.484883Z"}}